CVE-2021-41785: Use After Free
Published Aug 29, 2022
·Updated
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Affected Software
4 affected components
Foxit PDF Editor>=11.0<11.1
Foxit PDF Reader>=11.0<11.1
Foxit PhantomPDF<10.1.6
Microsoft Windows
Event History
Aug 29, 2022
CVE Published
via MITRE·04:53 AM
Data Sourced
via MITRE·04:53 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-41785.
2
What software versions are affected by this vulnerability?
Foxit PDF Reader versions before 11.1, PDF Editor versions before 11.1, and PhantomPDF versions before 10.1.6 are affected by this vulnerability.
3
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by triggering a use-after-free and executing arbitrary code through mishandled JavaScript.
4
What is the severity level of this vulnerability?
The severity level of this vulnerability is high with a CVSS score of 7.8.
5
How can I fix this vulnerability?
To fix this vulnerability, update Foxit PDF Reader, PDF Editor, and PhantomPDF to version 11.1 or higher.